From: "Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)" <hthakar@cisco.com>
To: openembedded-core@lists.openembedded.org
Cc: xe-linux-@cisco.com, external@cisco.com,
Hetvi Thakar <hthakar@cisco.com>
Subject: [OE-core][wrynose][PATCH] python3-pip: Fix CVE-2026-8643
Date: Sun, 16 Aug 2026 21:42:31 -0700 [thread overview]
Message-ID: <20260817044231.127184-1-hthakar@cisco.com> (raw)
From: Hetvi Thakar <hthakar@cisco.com>
This patch backports the upstream fix for CVE-2026-8643. The
commit is included in pip 26.1.2 and referenced in [1]. The public
CVE advisory is referenced in [2].
The selected commit is self-contained. Later upstream commits refactor
the validation to use a shared containment helper and update release
notes; they are not prerequisites for this fix.
[1] https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb
[2] https://github.com/advisories/GHSA-wf93-45jw-7689
Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
---
.../python/python3-pip/CVE-2026-8643.patch | 80 +++++++++++++++++++
.../python/python3-pip_26.0.1.bb | 4 +-
2 files changed, 83 insertions(+), 1 deletion(-)
create mode 100644 meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
diff --git a/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
new file mode 100644
index 0000000000..2f38ad0207
--- /dev/null
+++ b/meta/recipes-devtools/python/python3-pip/CVE-2026-8643.patch
@@ -0,0 +1,80 @@
+From 483d83c13c9d69c1916c06cab29991f6c2725cee Mon Sep 17 00:00:00 2001
+From: Damian Shaw <damian.peter.shaw@gmail.com>
+Date: Wed, 20 May 2026 15:20:25 -0400
+Subject: [PATCH] Reject entry point names that escape scripts dir (#14000)
+
+* Reject entry point names that escape scripts dir
+
+* NEWS ENTRY
+
+CVE: CVE-2026-8643
+Upstream-Status: Backport [https://github.com/pypa/pip/commit/8eb178480bd1a2b223f509fc430796b265158dfb]
+
+Backport Changes:
+- Omitted tests/unit/test_wheel.py because the pip 26.0.1 PyPI sdist
+ does not ship the upstream test suite and the OE recipe does not
+ enable ptest.
+
+(cherry picked from commit 8eb178480bd1a2b223f509fc430796b265158dfb)
+Signed-off-by: Hetvi Thakar <hthakar@cisco.com>
+---
+ news/14000.bugfix.rst | 2 ++
+ src/pip/_internal/operations/install/wheel.py | 26 ++++++++++++++++---
+ 2 files changed, 25 insertions(+), 3 deletions(-)
+ create mode 100644 news/14000.bugfix.rst
+
+diff --git a/news/14000.bugfix.rst b/news/14000.bugfix.rst
+new file mode 100644
+index 000000000..3b86f1b3b
+--- /dev/null
++++ b/news/14000.bugfix.rst
+@@ -0,0 +1,2 @@
++Reject ``console_scripts`` and ``gui_scripts`` entry points whose name would
++install a script outside the scripts directory.
+diff --git a/src/pip/_internal/operations/install/wheel.py b/src/pip/_internal/operations/install/wheel.py
+index 40097d6a7..231e40065 100644
+--- a/src/pip/_internal/operations/install/wheel.py
++++ b/src/pip/_internal/operations/install/wheel.py
+@@ -397,11 +397,31 @@ class MissingCallableSuffix(InstallationError):
+ )
+
+
+-def _raise_for_invalid_entrypoint(specification: str) -> None:
++def _script_within_dir(name: str, scripts_dir: str) -> bool:
++ """Return whether script ``name`` resolves to a path inside the ``scripts_dir``.
++
++ distlib joins the entry point name onto the scripts directory, so a name
++ with path separators or ``..`` components can resolve elsewhere.
++ """
++ root = os.path.normpath(scripts_dir)
++ dest = os.path.normpath(os.path.join(scripts_dir, name))
++ return dest.startswith(root + os.sep)
++
++
++def _raise_for_invalid_entrypoint(specification: str, scripts_dir: str) -> None:
+ entry = get_export_entry(specification)
+- if entry is not None and entry.suffix is None:
++ if entry is None:
++ return
++
++ if entry.suffix is None:
+ raise MissingCallableSuffix(str(entry))
+
++ if not _script_within_dir(entry.name, scripts_dir):
++ raise InstallationError(
++ f"Invalid script entry point name {entry.name!r}: the script "
++ f"would be installed outside the scripts directory ({scripts_dir})."
++ )
++
+
+ class PipScriptMaker(ScriptMaker):
+ # Override distlib's default script template with one that
+@@ -419,7 +439,7 @@ class PipScriptMaker(ScriptMaker):
+ def make(
+ self, specification: str, options: dict[str, Any] | None = None
+ ) -> list[str]:
+- _raise_for_invalid_entrypoint(specification)
++ _raise_for_invalid_entrypoint(specification, self.target_dir)
+ return super().make(specification, options)
+
+
diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
index 28af8f7ec7..3bea989958 100644
--- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb
+++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
@@ -24,7 +24,9 @@ LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=63ec52baf95163b597008bb46db68030 \
inherit pypi python_setuptools_build_meta
-SRC_URI += "file://no_shebang_mangling.patch"
+SRC_URI += "file://no_shebang_mangling.patch \
+ file://CVE-2026-8643.patch \
+ "
SRC_URI[sha256sum] = "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b296613346d8"
--
2.35.6
next reply other threads:[~2026-08-17 4:43 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 4:42 Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) [this message]
2026-09-02 8:34 ` [OE-core][wrynose][PATCH] python3-pip: Fix CVE-2026-8643 Yoann Congal
2026-09-03 6:43 ` [wrynose][PATCH] " Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260817044231.127184-1-hthakar@cisco.com \
--to=hthakar@cisco.com \
--cc=external@cisco.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=xe-linux-@cisco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.